CVE-2021-40348: Code Injection
Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to the installation setup. This can lead to the ability of an attacker to use --option to append arbitrary code to a root-owned file that eventually will be executed by the system. This is fixed in Uyuni spacewalk-admin 4.3.2-1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-40348.
What is the severity of CVE-2021-40348?
The severity of CVE-2021-40348 is critical (8.8).
Which software versions are affected by CVE-2021-40348?
Spacewalk 2.10 and Uyuni 2021.08 are affected by CVE-2021-40348.
How does CVE-2021-40348 allow code injection?
CVE-2021-40348 allows code injection through the un-sanitized configuration filename used by rhn-config-satellite.pl script.
Is there a fix available for CVE-2021-40348?
Yes, a fix is available. Please refer to the provided references for more information.